id: Cloud Data Exfiltration Response version: -1 name: Cloud Data Exfiltration Response description: "## Cloud Data Exfiltration Response\n\nThe Cloud Data Exfiltration Response playbook is designed to address data exfiltration activity alerts in the cloud environment. This playbook is intended for handling \"An identity performed a suspicious download of multiple cloud storage object\" alert.\nThe playbook supports AWS, GCP, and Azure and executes the following:\n- Enrichment involved assets. \n- Determines the appropriate verdict based on the data collected from the enrichment. \n- Cloud Persistence Threat Hunting:\n - Conducts threat hunting activities to identify any cloud persistence techniques\n- Verdict Handling:\n - Handles false positives identified during the investigation\n - Handles true positives by initiating appropriate response actions" starttaskid: "0" tasks: "0": id: "0" taskid: 22d468a7-b5b0-47bd-8376-e59f74fab8e1 type: start task: id: 22d468a7-b5b0-47bd-8376-e59f74fab8e1 version: -1 name: "" iscommand: false brand: "" description: '' nexttasks: '#none#': - "73" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 680, "y": -120 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "1": id: "1" taskid: 676a1dee-45cb-4f60-8e6a-125fa23d9e42 type: title task: id: 676a1dee-45cb-4f60-8e6a-125fa23d9e42 version: -1 name: Entity Enrichment type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "59" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1080, "y": 320 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "6": id: "6" taskid: 3c7469d0-c6e8-4523-8440-2b90681d38a2 type: title task: id: 3c7469d0-c6e8-4523-8440-2b90681d38a2 version: -1 name: Enumeration Alert Search type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "13" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 280, "y": 320 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "13": id: "13" taskid: 1bbbc703-b46d-4532-83c6-e51b27cf570d type: regular task: id: 1bbbc703-b46d-4532-83c6-e51b27cf570d version: -1 name: Search alerts for cloud enumeration activity description: |- Searches Cortex XSIAM alerts. A summarized version of this scrips is available with the summarizedversion argument. This automation runs using the default Limited User role, unless you explicitly change the permissions. For more information, see the section about permissions here: - For Cortex XSOAR 6 see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations - For Cortex XSOAR 8 Cloud see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script - For Cortex XSOAR 8.7 On-prem see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script scriptName: SearchIncidentsV2 type: regular iscommand: false brand: "" nexttasks: '#none#': - "78" scriptarguments: details: simple: '*enumeration*' fromdate: simple: 1 day ago query: complex: root: alert accessor: username transformers: - operator: FirstArrayElement - operator: uniq - operator: concat args: prefix: value: simple: (mitre_tactic_id_and_name:"TA0007 - Discovery") and (actor_effective_username:" suffix: value: simple: '")' separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 280, "y": 460 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "23": id: "23" taskid: 7edb2290-6dfc-4c91-899f-4a73b47ca242 type: title task: id: 7edb2290-6dfc-4c91-899f-4a73b47ca242 version: -1 name: Check IP Prevelance type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "43" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 680, "y": 320 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "28": id: "28" taskid: ef365d2c-9f1e-4d23-8c0d-370585b85f13 type: title task: id: ef365d2c-9f1e-4d23-8c0d-370585b85f13 version: -1 name: Enrichment type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "6" - "23" - "1" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 680, "y": 180 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "30": id: "30" taskid: 0bd1ea2c-e85f-4172-8763-772bfa9a3057 type: title task: id: 0bd1ea2c-e85f-4172-8763-772bfa9a3057 version: -1 name: Done type: title iscommand: false brand: "" description: '' separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1260, "y": 2570 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "31": id: "31" taskid: b2a335ad-2aaf-4e7a-8ccf-252137bebdd2 type: regular task: id: b2a335ad-2aaf-4e7a-8ccf-252137bebdd2 version: -1 name: Close Alert description: commands.local.cmd.close.inv script: Builtin|||closeInvestigation type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "30" scriptarguments: closeReason: simple: True Positive. separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 930, "y": 2400 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "32": id: "32" taskid: 9c4eb7f8-d21f-4ac7-83bc-167244ce5cb7 type: condition task: id: 9c4eb7f8-d21f-4ac7-83bc-167244ce5cb7 version: -1 name: Found malicious evidence based on enrichment data description: "This step will check the following and if one of those conditions match, this alert is malicious/suspicious:\n\n- Is there access to a backup bucket? \n- Check IP prevalence - if the IP is a known IP in the company\n- Is the IP malicious?\n- Is there an enumeration alert associated with the same user?\n- Is the IP known as one of the organization VPN address?\n- Is there minimum access to this bucket? Will be determined by a threshold." type: condition iscommand: false brand: "" nexttasks: '#default#': - "47" Malicious: - "64" separatecontext: false conditions: - label: Malicious condition: - - operator: isNotEmpty left: value: simple: IP.Malicious iscontext: true right: value: {} - operator: containsGeneral left: value: simple: foundIncidents.details iscontext: true right: value: simple: enumeration ignorecase: true - operator: isEqualString left: value: complex: root: Core.OriginalAlert.event accessor: is_bucket_name_backup_storage iscontext: true right: value: simple: "True" ignorecase: true - operator: isEqualString left: value: complex: root: Core.OriginalAlert.event accessor: is_caller_ip_organization_vpn_ip_address iscontext: true right: value: simple: "False" ignorecase: true - operator: lessThanOrEqual left: value: complex: root: Core.OriginalAlert.event accessor: cloud_provider_bucket_name_days_seen_count_bucket_object_download iscontext: true right: value: simple: "5" ignorecase: true continueonerrortype: "" view: |- { "position": { "x": 680, "y": 790 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "37": id: "37" taskid: f5f819b3-f6eb-4f10-837e-c6a859a1cf42 type: condition task: id: f5f819b3-f6eb-4f10-837e-c6a859a1cf42 version: -1 name: Review the alert findings description: "The enrichment process didn't identify any further suspicious activity.\nPlease review these alert findings and choose how to handle it.\n\nSuggested checklist for the analyst:\n- Check the environment of the bucket - Is it in QA / Dev / Alpha / Production? Is it should be publicly available? - Check the information in the bucket - Is there any PII? Any configurations that might be potentially harmful in the wrong hands (such as API keys).\nDid you find this alert to be malicious/suspicious?\nIf you choose yes, the playbook will continue with containment actions\nNo will execute 'Handle False Positive' sub-playbook.\nFinish Playbook will end the playbook." type: condition iscommand: false brand: "" nexttasks: Finish Playbook: - "30" "No": - "51" "Yes": - "76" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1260, "y": 1730 } } note: false timertriggers: [] ignoreworker: false message: to: subject: body: simple: |- The enrichment process didn't identify any further suspicious activity. Please review this alert findings and choose how to handle it. Suggested checklist for the analyst: - Check the environment of the bucket - Is it in QA / Dev / Alpha / Production? Is it should be publically available? - Check the information in the bucket - Is there any PII? Any configurations that might be potentially harmful in the wrong hands ( such as API keys). Did you find this alert to be malicious/suspicious? - If you choose yes, the playbook will continue with containment actions - No will execute 'Handle False Positive' sub-playbook. - Finish Playbook will end the playbook." methods: [] format: "" bcc: cc: timings: retriescount: 2 retriesinterval: 360 completeafterreplies: 1 completeafterv2: true completeaftersla: false replyOptions: - Yes - No - Finish Playbook skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "43": id: "43" taskid: 521b51bd-c579-4cf4-8d2e-aa8ad689b227 type: regular task: id: 521b51bd-c579-4cf4-8d2e-aa8ad689b227 version: -1 name: IP prevalence check description: Get the prevalence of an IP, identified by ip_address. script: '|||core-get-IP-analytics-prevalence' type: regular iscommand: true brand: "" nexttasks: '#none#': - "78" scriptarguments: ip_address: complex: root: alert accessor: hostip transformers: - operator: uniq separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 680, "y": 460 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "47": id: "47" taskid: a989b07f-5498-4e55-8f33-ee8d91c274a8 type: title task: id: a989b07f-5498-4e55-8f33-ee8d91c274a8 version: -1 name: 'Investigation ' type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "52" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1070, "y": 960 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "51": id: "51" taskid: c5e9aade-b872-48d6-87bd-2ed35118cd31 type: playbook task: id: c5e9aade-b872-48d6-87bd-2ed35118cd31 version: -1 name: Handle False Positive Alerts description: | This playbook handles false positive alerts. It creates an alert exclusion or alert exception, or adds a file to an allow list based on the alert fields and playbook inputs. playbookName: Handle False Positive Alerts type: playbook iscommand: false brand: "" nexttasks: '#none#': - "30" scriptarguments: FileSHA256: complex: root: alert accessor: initiatorsha256 ShouldCloseAutomatically: simple: "False" alertName: complex: root: alert accessor: name sourceIP: complex: root: alert accessor: hostip username: complex: root: alert accessor: username separatecontext: true continueonerrortype: "" loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": 1610, "y": 1900 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "52": id: "52" taskid: 063d3d5e-5b5d-478e-8941-ffd93ed418d3 type: title task: id: 063d3d5e-5b5d-478e-8941-ffd93ed418d3 version: -1 name: Threat Hunting type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "81" - "82" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1070, "y": 1100 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "57": id: "57" taskid: 5ebfddc7-a504-4482-82a7-d0dc69f80a03 type: title task: id: 5ebfddc7-a504-4482-82a7-d0dc69f80a03 version: -1 name: No Malicious activity identified type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "37" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1260, "y": 1590 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "59": id: "59" taskid: c5d2b9f8-b039-41e6-8c04-08c23a7abe46 type: regular task: id: c5d2b9f8-b039-41e6-8c04-08c23a7abe46 version: -1 name: Check IP Reputation description: Checks the specified IP address against the AbuseIP database. script: '|||ip' type: regular iscommand: true brand: "" nexttasks: '#none#': - "78" scriptarguments: ip: complex: root: alert accessor: hostip transformers: - operator: uniq separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1080, "y": 460 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "61": id: "61" taskid: b2e0de5a-b3dc-4c56-8dd3-1d07e3166289 type: condition task: id: b2e0de5a-b3dc-4c56-8dd3-1d07e3166289 version: -1 name: Found any persistence evidences or user abnormal activity? description: Checks if results are returned from the Cloud Threat Hunting - Persistence and Cloud User Investigation - Generic sub-playbooks. type: condition iscommand: false brand: "" nexttasks: '#default#': - "57" "yes": - "64" separatecontext: false conditions: - label: "yes" condition: - - operator: isNotEmpty left: value: simple: AWSQuery iscontext: true right: value: {} - operator: isNotEmpty left: value: simple: GCPQuery iscontext: true - operator: isNotEmpty left: value: simple: AwsMFAConfigCount iscontext: true - operator: isNotEmpty left: value: simple: AwsUserRoleChangesCount iscontext: true - operator: isNotEmpty left: value: simple: AwsSuspiciousActivitiesCount iscontext: true - operator: isNotEmpty left: value: simple: AwsScriptBasedUserAgentCount iscontext: true - operator: isNotEmpty left: value: simple: GcpSuspiciousApiUsage iscontext: true - operator: isNotEmpty left: value: simple: GsuiteUnusualLoginAllowedCount iscontext: true - operator: isNotEmpty left: value: simple: GsuiteUserPasswordLeaked iscontext: true - operator: isNotEmpty left: value: simple: AzureScriptBasedUserAgentEvents iscontext: true continueonerrortype: "" view: |- { "position": { "x": 1070, "y": 1410 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "64": id: "64" taskid: cf29d1b9-edb3-4f54-8b84-1864f001e721 type: title task: id: cf29d1b9-edb3-4f54-8b84-1864f001e721 version: -1 name: Malicious Activity identified description: Optionally increases the alert severity to the new value if it is greater than the existing severity. type: title iscommand: false brand: "" nexttasks: '#none#': - "76" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 680, "y": 1590 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "73": id: "73" taskid: e5c52d38-39a3-40e1-83c8-6a43efbf30ef type: regular task: id: e5c52d38-39a3-40e1-83c8-6a43efbf30ef version: -1 name: Get cloud extra data description: Returns information about each alert ID. script: '|||core-get-cloud-original-alerts' type: regular iscommand: true brand: "" nexttasks: '#none#': - "28" scriptarguments: alert_ids: complex: root: alert accessor: id filter_alert_fields: simple: "false" ignore-outputs: simple: "false" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 680, "y": 20 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 2 isoversize: false isautoswitchedtoquietmode: false "76": id: "76" taskid: 3dd56123-770c-4681-841b-86dd7f338994 type: title task: id: 3dd56123-770c-4681-841b-86dd7f338994 version: -1 name: Containment Plan type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "79" - "83" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 680, "y": 1900 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "78": id: "78" taskid: 4e2adb26-6b33-43af-8278-818c497109f7 type: title task: id: 4e2adb26-6b33-43af-8278-818c497109f7 version: -1 name: Set Alert Verdict type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "32" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 680, "y": 640 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "79": id: "79" taskid: a5f34eb1-6d18-4061-8f2e-e71458a6e109 type: playbook task: id: a5f34eb1-6d18-4061-8f2e-e71458a6e109 version: -1 name: Cloud Response - Generic description: |- This playbook provides response playbooks for: - AWS - Azure - GCP The response actions available are: - Terminate/Shut down/Power off an instance - Delete/Disable a user - Delete/Revoke/Disable credentials - Block indicators playbookName: Cloud Response - Generic type: playbook iscommand: false brand: "" nexttasks: '#none#': - "31" scriptarguments: AWS-userRemediationType: simple: Revoke Azure-userRemediationType: simple: Disable GCP-accessKeyRemediationType: simple: Disable GCP-userRemediationType: simple: Disable autoAccessKeyRemediation: simple: "False" autoBlockIndicators: complex: root: inputs.autoBlockIndicators autoResourceRemediation: simple: "False" autoUserRemediation: simple: ${inputs.autoUserRemediation} cloudProvider: complex: root: alert accessor: cloudprovider username: complex: root: alert.username filters: - - operator: notStartWith left: value: simple: alert.username iscontext: true right: value: simple: key1( ignorecase: true - operator: notStartWith left: value: simple: alert.username iscontext: true right: value: simple: key2( separatecontext: false continueonerrortype: "" loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": 930, "y": 2040 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "81": id: "81" taskid: f860728f-cbbe-4cad-8d99-e22e8b8043a8 type: playbook task: id: f860728f-cbbe-4cad-8d99-e22e8b8043a8 version: -1 name: Cloud Threat Hunting - Persistence description: |- --- ## Cloud Threat Hunting - Persistence Playbook The playbook is responsible for hunting persistence activity in the cloud. It supports AWS, GCP, and Azure - one at a time. ### Hunting Queries The playbook executes hunting queries for each provider related to each of the following: 1. IAM 2. Compute Resources 3. Compute Functions ### Indicator Extraction If relevant events are found during the search, indicators will be extracted using the `ExtractIndicators-CloudLogging` script. --- playbookName: Cloud Threat Hunting - Persistence type: playbook iscommand: false brand: "" nexttasks: '#none#': - "61" scriptarguments: AWSAccessKeyID: complex: root: Core.OriginalAlert.event accessor: identity_invoked_by_uuid AWSTimespan: complex: root: alert accessor: timestamp transformers: - operator: ModifyDateTime args: variation: value: simple: 2 hours ago - operator: Cut args: delimiter: value: simple: + fields: value: simple: "1" AzureTimespan: simple: 2h GCPProjectName: complex: root: alert accessor: cloudproject GCPTimespan: complex: root: alert accessor: timestamp transformers: - operator: ModifyDateTime args: variation: value: simple: 2 hours ago - operator: replace args: limit: {} replaceWith: value: simple: Z toReplace: value: simple: "+00:00" cloudProvider: complex: root: alert accessor: cloudprovider region: complex: root: alert accessor: region username: complex: root: alert accessor: username separatecontext: false continueonerrortype: "" loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": 1070, "y": 1240 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "82": id: "82" taskid: 4b344065-3e29-433f-81ac-a7f34eac4b3a type: playbook task: id: 4b344065-3e29-433f-81ac-a7f34eac4b3a version: -1 name: Cloud User Investigation - Generic description: | This playbook performs an investigation on a specific user in cloud environments, using queries and logs from Azure Log Analytics, AWS CloudTrail, G Suite Auditor, and GCP Logging. playbookName: Cloud User Investigation - Generic type: playbook iscommand: false brand: "" nexttasks: '#none#': - "61" scriptarguments: AwsTimeSearchFrom: simple: "1" AzureSearchTime: simple: ago(1d) GcpProjectName: complex: root: alert.cloudproject accessor: cloudproject GcpTimeSearchFrom: simple: "1" MfaAttemptThreshold: simple: "10" Username: complex: root: alert.username filters: - - operator: notStartWith left: value: simple: alert.username iscontext: true right: value: simple: key1( ignorecase: true - operator: notStartWith left: value: simple: alert.username iscontext: true right: value: simple: key2( cloudProvider: complex: root: alert accessor: cloudprovider failedLogonThreshold: simple: "20" separatecontext: true continueonerrortype: "" loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": 1550, "y": 1240 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "83": id: "83" taskid: af782aef-ba76-45b9-87a3-e6e385bebb1e type: condition task: id: af782aef-ba76-45b9-87a3-e6e385bebb1e version: -1 name: Should rotate the credentials automatically? description: Whether to rotate the credentials automatically. type: condition iscommand: false brand: "" nexttasks: '#default#': - "31" "yes": - "84" separatecontext: false conditions: - label: "yes" condition: - - operator: isEqualString left: value: simple: inputs.autoUserRemediation iscontext: true right: value: simple: "true" ignorecase: true continueonerrortype: "" view: |- { "position": { "x": 430, "y": 2040 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "84": id: "84" taskid: ff0f8a46-1a28-46b7-81bf-512130aefb3a type: playbook task: id: ff0f8a46-1a28-46b7-81bf-512130aefb3a version: -1 name: Cloud Credentials Rotation - Generic description: |- ## **Cloud Credentials Rotation - Generic** This comprehensive playbook combines the remediation steps from AWS, Azure, and GCP sub-playbooks into a single, cohesive guide. Regardless of which Cloud Service Provider (CSP) you're working with, this playbook will direct you to the relevant steps, ensuring swift and effective response. The primary objective is to offer an efficient way to address compromised credentials across different cloud platforms. By consolidating the key steps from AWS, Azure, and GCP, it minimizes the time spent searching for platform-specific procedures and accelerates the remediation process, ensuring the highest level of security for your cloud environments. ## **Integrations for Each Sub-Playbook** In order to seamlessly execute the actions mentioned in each sub-playbook, specific integrations are essential. These integrations facilitate the automated tasks and processes that the playbook carries out. Here are the required integrations for each sub-playbook: ### **AWS Sub-Playbook:** 1. [**AWS - IAM**](https://xsoar.pan.dev/docs/reference/integrations/aws---iam): Used to manage AWS Identity and Access Management. 2. [**AWS - EC2**](https://xsoar.pan.dev/docs/reference/integrations/aws---ec2): Essential for managing Amazon Elastic Compute Cloud (EC2) instances. ### **GCP Sub-Playbook:** 1. [**Google Workspace Admin**](https://xsoar.pan.dev/docs/reference/integrations/g-suite-admin): Manages users, groups, and other entities within Google Workspace. 2. [**GCP-IAM**](https://xsoar.pan.dev/docs/reference/integrations/gcp-iam): Ensures management and control of GCP's Identity and Access Management. ### **Azure Sub-Playbook:** 1. [**Microsoft Graph Users**](https://xsoar.pan.dev/docs/reference/integrations/microsoft-graph-user): Manages users and related entities in Microsoft Graph. 2. [**Microsoft Graph Applications**](https://xsoar.pan.dev/docs/reference/integrations/microsoft-graph-applications): Manages applications within Microsoft Graph. playbookName: Cloud Credentials Rotation - Generic type: playbook iscommand: false brand: "" nexttasks: '#none#': - "31" scriptarguments: AWS-accessKeyID: simple: ${Core.OriginalAlert.event.identity_orig.accessKeyId} AWS-instanceID: complex: root: alert.username filters: - - operator: containsGeneral left: value: simple: alert.username iscontext: true right: value: simple: i- transformers: - operator: Cut args: delimiter: value: simple: / fields: value: simple: "2" AWS-newInstanceProfileName: simple: ${inputs.AWS-newInstanceProfileName} AWS-newRoleName: simple: ${inputs.AWS-newRoleName} AWS-roleNameToRestrict: simple: ${inputs.AWS-roleNameToRestrict} AWS-userID: simple: ${alert.username} Azure-AppID: simple: ${Core.OriginalAlert.event.identity_orig.claims.appid} Azure-ObjectID: complex: root: Core.OriginalAlert.event.identity_orig accessor: claims transformers: - operator: Stringify - operator: RegexExtractAll args: error_if_no_match: {} ignore_case: {} multi_line: {} period_matches_newline: {} regex: value: simple: http://schemas.microsoft.com/identity/claims/objectidentifier":"\w{8}\-\w{4}\-\w{4}\-\w{4}\-\w{12} unpack_matches: {} - operator: ExtractInbetween args: from: value: simple: http://schemas.microsoft.com/identity/claims/objectidentifier":" to: value: simple: '"' Azure-userID: simple: ${alert.username} GCP-SAEmail: simple: ${Core.OriginalAlert.event.identity_orig.principalEmail} GCP-cloudProject: simple: ${alert.cloudproject} GCP-userID: simple: ${alert.username} GCP-zone: simple: ${Core.OriginalAlert.event.zone} RemediationType: simple: ${inputs.credentialsRemediationType} cloudProvider: simple: ${alert.cloudprovider} identityType: simple: ${alert.cloudidentitytype} shouldCloneSA: simple: ${inputs.shouldCloneSA} separatecontext: true continueonerrortype: "" loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": 430, "y": 2230 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false view: |- { "linkLabelsPosition": { "32_47_#default#": 0.28, "32_64_Malicious": 0.21, "37_30_Finish Playbook": 0.15, "61_57_#default#": 0.61, "61_64_yes": 0.35, "83_31_#default#": 0.38, "83_84_yes": 0.44 }, "paper": { "dimensions": { "height": 2755, "width": 1710, "x": 280, "y": -120 } } } inputs: - key: autoUserRemediation value: simple: "False" required: false description: 'Whether to execute the user remediation automatically. (Default: False)' playbookInputQuery: - key: autoBlockIndicators value: simple: "False" required: false description: 'Whether to execute the block remediation automatically. (Default: False)' playbookInputQuery: - key: credentialsRemediationType value: simple: Reset required: false description: |- The response playbook provides the following remediation actions using AWS, MSGraph Users, GCP and GSuite Admin: Reset: By entering "Reset" in the input, the playbook will execute password reset. Supports: AWS, MSGraph Users, GCP and GSuite Admin. Revoke: By entering "Revoke" in the input, the GCP will revoke the access key, GSuite Admin will revoke the access token and the MSGraph Users will revoke the session. Supports: GCP, GSuite Admin and MSGraph Users. Deactivate - By entering "Deactivate" in the input, the playbook will execute access key deactivation. Supports: AWS. ALL: By entering "ALL" in the input, the playbook will execute the all remediation actions provided for each CSP. playbookInputQuery: - key: shouldCloneSA value: simple: "False" required: false description: |- Whether to clone the compromised SA before putting a deny policy to it. Supports: AWS. True/False playbookInputQuery: - key: AWS-newInstanceProfileName value: {} required: false description: The new instance profile name to assign in the clone service account flow. playbookInputQuery: - key: AWS-newRoleName value: {} required: false description: The new role name to assign in the clone service account flow. playbookInputQuery: - key: AWS-roleNameToRestrict value: {} required: false description: If provided, the role will be attached with a deny policy without the compute instance analysis flow. playbookInputQuery: outputs: [] tests: - No tests (auto formatted) marketplaces: - marketplacev2 - platform fromversion: 6.8.0 supportedModules: - xsiam